Secure key distribution using sequential weak values

ABSTRACT

A method is provided for distributing a random list of binary values between first and second parties. The method includes sending photons from the second party into an interferometer at a first beam splitter; performing a first weak measurement on photons as a first pointer result into a first time-ordered list for photons; performing a second weak measurement by the first party on photons that pass through a second beam splitter as being a second pointer result into a second time-ordered list; recording identification for first and second detectors that the photons arrive via a third beam splitter as respective first and second detector registrations for collecting in a third time-ordered list as respective first and second detection lists; determining first and second averages of the respective first and second detection lists; and comparing the averages to verify existence of a non-trivial difference that indicates secure communication status of the element&#39;s binary value.

STATEMENT OF GOVERNMENT INTEREST

The invention described was made in the performance of official duties by one or more employees of the Department of the Navy, and thus, the invention herein may be manufactured, used or licensed by or for the Government of the United States of America for governmental purposes without the payment of any royalties thereon or therefor.

BACKGROUND

The invention relates generally to quantum communication (QC). In particular, this invention relates to quantum key distribution using weak measurement of sequentially emitted photons.

Secure communication involves exchange of information between intended communicants, e.g., Alice and Bob, without an eavesdropper, e.g., Eve, from unauthorized interception of the information message. Quantum cryptography represents an example of this process. Such methods include development of conventional quantum key distribution (QKD) protocol. Separately, weak measurements of quantum states have been investigated for various purposes.

The earliest conventional QKD protocol involves a method of securely communicating a private key from one party to another for use in onetime pad encryption. This procedure is documented by Charles Bennett and Gilles Brassard in “Quantum Cryptography: Public Key Distribution and Coin Tossing”, at the International Conference on Computers, Systems & Signal Processing, December 1984, and commonly referred to as BB84. See http://www.research.ibm.com/people/b/bennetc/bennettc198469790513.pdf for details.

The weak value of an observable of a quantum system at an intermediate time is equally determined by both the initial state of the system and the state resulting from a final projective measurement. In this manner, the weak value contains a signature of the correlations between past and future states of the system. The time-symmetric formulation of quantum mechanics first introduced the concepts of weak measurement and weak values. See Y. Aharonov et al. “How . . . measurement . . . ”, Phys. Rev. Ltrs., 60 (1988) 1351; Y. Aharonov et al., “Properties of a quantum system . . . ” Phys. Rev. A, 41 (1990) 11; B. Reznik et al., “On the time symmetric formulation . . . ”, Phys. Rev. A, 52 (1995) 2538. While debate continues over the meaning of weak values, their utility has been experimentally demonstrated in many areas, particularly in relation to Hardy's Paradox. See Y. Aharonov et al., “Revisiting Hardy's Paradox . . . ”, Phys. Ltrs. A, 301 (2002) 130; K. Yokota et al., “Direct observation . . . ”, New J. of Phys., 11 (2009) 033011; J. Lundeen et al., “Experimental Joint Weak Measurement . . . ”, Phys. Rev. Ltrs., 102 (2009) 020404; D. Starling et al., “Precision frequency measurements”, Phys. Rev. A, 82 (2010) 062822; and N. Brunner et al., “Measuring small longitudinal phase shifts . . . ”, Phys. Rev. Ltrs., 105 (2010) 010405.

SUMMARY

Conventional communication methods and systems yield disadvantages addressed by various exemplary embodiments of the present invention. In particular, a communication method is provided for securely transmitting a shared random key between first and second parties. The first party (Alice) has a mirror. The second party (Bob) has an interferometer pair that includes first, second and third beam splitters, and first and second detectors.

The process for various exemplary embodiments include: sending a plurality of photons from Bob into the interferometer at the first beam splitter; performing a first weak measurement on each photon as |1

1|₁ being a first pointer result; incorporating the first pointer result into a first time-ordered list L₁ for each photon; performing a second weak measurement by Alice on each photon that passes through the second beam splitter to the first mirror as |1

1|₂ being a second pointer result; incorporating the second pointer result into a second time-ordered list L₂ for each photon that passes through; recording identification as one of the first and second detectors that each photon arrives via the third beam splitter as respective first and second detector registrations.

The exemplary process further includes: distinguishing the first and second detector registrations into a third time-ordered list F for each photon; collecting the first and second detector registrations from the third time-ordered list F that correspond to the first time-ordered list L₁ as respective first and second detection lists B₁ and B₂; determining first and second averages of the respective first and second detection lists; and comparing the first and second averages to verify existence of a non-trivial difference that indicates secure communication status.

Additional exemplary embodiments provide a method that further includes: sending by the second party to the first party a transfer list from the second time-ordered list L₂ in one of an altered form to transmit a “0” and an unaltered form to transmit a “1”, the altered form shifting elements of each the second pointer result; collecting the first and second detector registrations from the third time-ordered list F corresponding to the transfer list as respective third and fourth detection lists A₁ and A₂; multiplying respective elements from the first and third detection lists to obtain a first product list R₁, and from the second and fourth detection lists to obtain a second product list R₂; and determining third and fourth averages of respective the first and second product lists, such that the “0” sent from the second party corresponds to both the third and fourth averages being zero, and the “1” sent from the second party corresponds to a ratio between the third and fourth averages being minus one.

BRIEF DESCRIPTION OF THE DRAWINGS

These and various other features and aspects of various exemplary embodiments will be readily understood with reference to the following detailed description taken in conjunction with the accompanying drawings, in which like or similar numbers are used throughout, and in which:

FIG. 1 is a plan diagram view of a twin Mach-Zehnder Interferometer; and

FIG. 2 is a plan diagram view of a communication arrangement.

DETAILED DESCRIPTION

In the following detailed description of exemplary embodiments of the invention, reference is made to the accompanying drawings that form a part hereof, and in which is shown by way of illustration specific exemplary embodiments in which the invention may be practiced. These embodiments are described in sufficient detail to enable those skilled in the art to practice the invention. Other embodiments may be utilized, and logical, mechanical, and other changes may be made without departing from the spirit or scope of the present invention. The following detailed description is, therefore, not to be taken in a limiting sense, and the scope of the present invention is defined only by the appended claims.

In accordance with a presently preferred embodiment of the present invention, the components, process steps, and/or data structures may be implemented using various types of operating systems, computing platforms, computer programs, and/or general purpose machines. In addition, those of ordinary skill in the art will readily recognize that devices of a less general purpose nature, such as hardwired devices, or the like, may also be used without departing from the scope and spirit of the inventive concepts disclosed herewith. General purpose machines include devices that execute instruction code. A hardwired device may constitute an application specific integrated circuit (ASIC) or a floating point gate array (FPGA) or other related component.

Various exemplary embodiments provide a secure communication method that utilizes the properties of the sequential weak values of a quantum observable to prevent eavesdropping. Due to the different quantum resource utilized, the exemplary communication protocol potentially has advantages over traditional quantum key distribution (QKD) methods. A fundamentally better tolerance to optical losses represents one very important potential advantage.

This disclosure describes a weak value method to enable communication of a shared secure key between two parties (Alice and Bob) that does not rely on traditional encryption methods, nor the use of conventional QKD methods. This exemplary quantum communication (QC) process remains nevertheless secure against an eavesdropper (Eve). This weak value communication protocol utilizes the properties of quantum systems in a novel manner to enable security. Instead of relying on the no-cloning property as does single photon based QKD, or Bell non-locality as does entanglement based QKD, this exemplary communication protocol utilizes the resource of the temporal non-locality of weak values of a quantum system.

Alice possesses a “raw key” list of random binary values. On conclusion of transmitting the raw key's elements, Alice and Bob implement classical information error correction and privacy amplification to distill a smaller shared private key that is secure. These techniques of error correction and privacy amplification are well established in the art. See e.g., C. Bennett et al., “Generalized Privacy Amplification”, IEEE Trans. on Info. Theory, 41 (1995) 1915.

In association with QKD communication protocol, a brief review of the concepts of weak measurement and weak values is presented. Y. Aharonov introduced the notion of the weak value of a quantum mechanical observable over two decades ago (in above citations). This weak value is experimentally obtained from the result of measurements performed upon a pre-selected and post-selected (PPS) ensemble of quantum systems when the interaction between the measurement apparatus and each system is sufficiently weak.

Unlike the standard strong measurement of a quantum mechanical observable, which disturbs the measured system and “collapses” its state into an eigenstate of the observable, a weak measurement does not appreciably disturb the quantum system, and yields the weak value as the measured value of the observable. This is possible because very little information about the observable is extracted in a single weak measurement. Experimentally determining the weak value requires performing weak measurements on each member of a large ensemble of identical PPS systems and averaging the resulting values.

The standard (i.e., conventional) formulation of quantum mechanics describes a quantum system at a reference time t₀ using a state evolving from the past to t₀. The time-symmetric reformulation of quantum mechanics (TSQM), described in Reznik et al., uses also a second state which can be interpreted as a state evolving backward in time from the future to t₀. The weak values measured at time t₀ are influenced by this post-selected state. Many experiments have verified the surprising and counter-intuitive aspects of weak values, e.g., weak values can lie far outside the associated observable's eigenvalue spectrum and can be complex valued, as reported in the Hardy's paradox references cited above.

Weak measurements can be described using the general von Neumann model of quantum measurement. See the Aharanov references and J. Tollaksen, “Pre- and post-selection . . . ”, J. of Phys. A, 40 (2007) 9033. Consider an observable A (i.e., a quantum physical characteristic subject to observation) pertaining to a quantum system pre-selected to be in the ket state |ψ_(in)

, where ψ_(in) represents the pre-select wave-function of the vector space. The interaction Hamiltonian H_(int) describing the system and measuring device (MD) is the interaction:

H _(int) =−g(t){circumflex over (Q)} _(MD) Â,  (1)

where {circumflex over (Q)}_(MD) is the position operator for the MD and g(t) is the interaction's coupling strength.

The evolution operator U_(meas) for the system and MD is then given by the relation:

U _(meas)=exp[−ig{circumflex over (Q)} _(MD) Â],  (2)

where the coupling strength g, defined by g=∫g(t)dt, is integrated over the interaction time interval 2ε (from time t₀−ε to t₀+ε). The measurement interaction is weakened by minimizing gΔQ_(MD). Let the MD's initial state |Φ> be a real Gaussian pointer with unit variance in momentum. Then the weakness of the measurement can be established (i.e., set) by setting g<<1, and ΔQ_(MD)=1. This enables the following approximation:

exp[−ig{circumflex over (Q)} _(MD) Â]ψ _(in)

|Φ

≅[1−ig{circumflex over (Q)} _(MD) Â]

a _(i) |Φ

a _(i)

|Φ

,  (3)

where |a_(i)

represents the eigenstate of the operator A with eigenvalue a_(i).

The final state of the measuring device can be seen to be a superposition of Gaussians in momentum space each of which is shifted by ga_(i) where the a_(i) are eigenvalues of Â. Thus, MD is a Gaussian with the mean shifted by g

Â

. The measurement can be shown to yield “information without disturbance” in the limit of vanishing g, by the following process. First, the important result from Tollaksen indicates that:

Â|Ψ

=<Â

|Ψ

+ΔA|Ψ _(⊥)

_(,)  (4)

where ΔA is the variance of Â, and |Ψ_(⊥)

is a disturbance state such that

Ψ|Ψ_(⊥)

=0, (i.e., zero probability amplitude for Ψ collapsing to Ψ_(⊥)). This obtains:

[1−ig{circumflex over (Q)} _(MD) Â]|ψ _(in)

=[1−ig{circumflex over (Q)} _(MD)

Â

]|ψ _(in)

−ig{circumflex over (Q)} _(MD) ΔA|ψ _(in⊥)

.  (5)

From this one can observe that the probability of the state remains unchanged after the weak measurement interaction constitutes:

$\begin{matrix} {{{{\langle{\psi_{in}}\rangle}{\langle{\psi_{in}}\rangle}} = {\frac{1 + {{g^{2}\left( {\overset{\Cap}{Q}}_{MD} \right)}^{2}{\langle\overset{\Cap}{A}\rangle}^{2}}}{1 + {{g^{2}\left( {\overset{\Cap}{Q}}_{MD} \right)}^{2}{\langle{\overset{\Cap}{A}}^{2}\rangle}}}->1}},{{{as}\mspace{14mu} g}->0.}} & (6) \end{matrix}$

Also the probability that the state is disturbed can be given by the relation:

$\begin{matrix} {{{{\langle{\psi_{{in}\bot}}\rangle}{\langle{\psi_{{in}\bot}}\rangle}} = {\frac{1 + {{g^{2}\left( {\overset{\Cap}{Q}}_{MD} \right)}^{2}{\langle{\Delta A}\rangle}^{2}}}{1 + {{g^{2}\left( {\overset{\Cap}{Q}}_{MD} \right)}^{2}{\langle{\overset{\Cap}{A}}^{2}\rangle}}}->1}},{{{as}\mspace{14mu} g}->0.}} & (7) \end{matrix}$

The probability to disturb the state falls off as g², while the shift in the measurement pointer is only reduced linearly in coupling strength g. This establishes that in principle one can couple a measuring device to a system and in the weak limit obtain information about an observable, with minimal disturbance to the state (i.e., such that the state is not significantly disturbed). This idealization neglects terms g² and higher.

The results of a weak measurement for a member of a PPS ensemble can be determined by rewriting the expectation value of Â as:

$\begin{matrix} \begin{matrix} {{\langle\overset{\Cap}{A}\rangle} = {\langle{\psi_{in}{\left\lbrack {\sum\limits_{j}{{\psi_{fin}\rangle}_{j}{\langle\psi_{fin}}}} \right\rbrack \psi_{in}}}\rangle}} \\ {{= {\sum\limits_{j}{{_{j}{\langle{{\psi_{fin}\psi_{in}}\rangle}}^{2}}\frac{\,_{j}{\langle{\psi_{fin}{\overset{\Cap}{A}}\psi_{in}}\rangle}}{\,_{j}{\langle{\psi_{fin}\psi_{in}}\rangle}}}}},} \end{matrix} & (8) \end{matrix}$

where j represents the summation increment for the eigenvalues of the observable that is strongly measured to produce the final state of the system. Thus, |ψ_(fin)

_(j) is the post-selected final state of the system where the j^(th) eigenvalue is observed.

With the states |ψ_(fin)

_(j) interpreted as the outcomes of the final ideal measurements on the system, then the specification of a particular j determines a particular PPS ensemble (assuming that all of the initial states are identical). The weak value of the observable Â for the system (of the j increment) preselected in the state |ψ_(in)

and post-selected in the state |ψ_(fin)

is then defined to be the quantity:

$\begin{matrix} {\left( A_{w} \right)^{j} \equiv {\frac{\,_{j}{\langle{\psi_{fin}{\overset{\Cap}{A}}\psi_{in}}\rangle}}{\,_{j}{\langle{\psi_{fin}\psi_{in}}\rangle}}.}} & (9) \end{matrix}$

The expectation value of any observable can be interpreted as an average of weak values (A_(w))^(j) taken over all of the different PPS ensembles. The weighting factor |_(j)

ψ_(fin)|Â|ψ_(in)

|² represents the probability of any single system to belong to the particular PPS defined by the outcome state |ψ_(fin)

. The wave-function of the measuring device after the weak measurement interaction and the post-selection is given by:

$\begin{matrix} \begin{matrix} {{\langle{P_{MD}{{\langle{\psi_{fin}{{\exp\left\lbrack {{- i}\; g{\overset{\Cap}{Q}}_{MD}\overset{\Cap}{A}} \right\rbrack}\rangle}}}\Phi}}\rangle} \cong {\langle{P_{MD}{{{{\langle{\psi_{fin}\psi_{in}}\rangle}\left\{ {1 + {i\; g{\overset{\Cap}{Q}}_{MD}\frac{\langle{\psi_{fin}{\overset{\Cap}{A}}\psi_{in}}\rangle}{\langle{\psi_{fin}\psi_{in}}\rangle}}} \right\} {\psi_{in}\rangle}}\Phi}\rangle}}}} \\ {{= {{\langle{\psi_{fin}\psi_{in}}\rangle}{\langle{P_{MD}{{\exp \left\lbrack {{- i}\; g{\overset{\Cap}{Q}}_{MD}\overset{\Cap}{A}} \right\rbrack}}\Phi}\rangle}}},} \end{matrix} & (10) \end{matrix}$

where P_(MD) represents momentum of the MD (measurement device).

Thus for a weak measurement of the observable Â on a particular member of a PPS ensemble, the MD state is shifted by the weak value A_(w) and the expectation value of the MD momentum will be

P_(MD)

=gRe(A_(w)). The weak value A_(w) is in general complex and its magnitude can lie far outside operator Â's eigenvalue spectrum. Note that because the interaction is very weak, the shift is very small in relation to the uncertainty of the MD. This indicates that a sufficiently large ensemble of identical PPS systems and measuring devices would be necessary in order to accurately determine the pointer shift and therefore accurately determine the weak value.

After the post-selection is made and every MD can be associated with a particular PPS ensemble, each of the MD systems is ideally measured, collapsing its wavefunction to a particular pointer value. By taking the average of all pointer values from the MD's for each PPS ensemble one can determine the weak value of the observable with an uncertainty that is proportional to 1/√{square root over (N)}, where N is the number of members of the particular PPS ensemble.

In the more general case when the system being measured evolves in time between the initial pre-selection (t=t_(in)) and the weak measurement interaction (t=t₀) via the unitary U, as well as from the weak measurement until the final post-selection (t=t_(fin)) via V, the weak value is given by:

$\begin{matrix} {A_{w} \equiv {\frac{\langle{\psi_{fin}{\overset{\Cap}{A}}\psi_{in}}\rangle}{\langle{\psi_{fin}\psi_{in}}\rangle}.}} & (11) \end{matrix}$

One can consider the weak measurement of two different observables, Â₁ and Â₂, measured at two different times t₁ and t₂, between the initial and final states of the system. The system evolves under U from |ψ_(in)

to t=t₁, under V between the two weak measurements (i.e., from t=t₁ until t=t₂), and finally under W from t=t₂ until the post-selected state |ψ_(fin)

_(j). The sequential weak value of Â₁ and Â₂ is defined in to be:

$\begin{matrix} {{\left( {A_{2},A_{1}} \right)_{w} = \frac{\langle{\psi_{fin}{{W{\overset{\Cap}{A}}_{2}V{\overset{\Cap}{A}}_{1}U}}\psi_{in}}\rangle}{\langle{\psi_{fin}{{WVU}}\psi_{in}}\rangle}},} & (12) \end{matrix}$

in which U, V and W represent successive unitary states between weak measurements.

Experimentally, the sequential weak value (SWV) of the two observables can be determined from the results for the individual weak measurements. Empirical studies have shown that the expectation of the product of weak measurement results are related to the sequential weak value by:

$\begin{matrix} {{{\langle{P_{1}P_{2}}\rangle} = {\frac{1}{2}g_{1}g_{2}{{Re}\left\lbrack {\left( {A_{2},A_{1}} \right)_{w} + {\left( A_{1} \right)_{w}{\overset{\_}{\left( A_{2} \right)}}_{w}}} \right\rbrack}}},} & (13) \end{matrix}$

where P_(i) is the pointer value obtained from the MD weakly measuring the observable Â_(i). See G. Mitchison et al. “Sequential weak measurement”, Phys. Rev. A, 76 (2007) 062105. This enables one to infer the SWV from the results of the individual weak measurements results of each operator. It is important to note that in general:

(A ₂ ,A ₁)_(w)≠(A ₂)_(w)·(A ₁)_(w).  (14)

This connotes the central property of SWV's to be exploited in the secure communication protocol detailed in following paragraphs. This property is due to the correlation that exists between the statistics of the individual WM pointer results for the each member of the PPS ensemble.

This correlation results from the temporally nonlocal character of weak values arising from the weak value of an operator being defined by both the initial and final states of the system. The experimentally accessible quantity

P₁P₂

is quadratic in the coupling constants. This means that one would need to obtain many more individual WM pointer values in order to accurately determine the sequential weak value (A₂, A₁)_(w) as compared to the individual weak values (A₂)_(w) and (A₁)_(w).

The following paragraphs describe embodiments for a particular quantum optical system and focus on the properties of the individual and sequential weak values of two specific operators. This optical arrangement constitutes a central part of the secure communication protocol. FIG. 1 illustrates the configuration under consideration of a twin Mach-Zehnder interferometer (MZI). The left portion MZI #1 is tuned so that all photons entering from the lower side always exit inside the second beam-splitter on the upper side.

In particular, FIG. 1 shows a plan diagram view 100 of the twin MZI. A source (e.g., a laser beam) emits a photon 110. The MZI includes three beam splitters 115, 120 and 125, along with four mirrors 130, 135, 140 and 145. In addition, the MCI includes first and second weak measurement devices: WM1 as 150 and WM2 as 155, as well as first and second detectors: D₁ as 160 and D₂ as 165. The photon 110 reaches the first beam splitter 115, which directs the photon to either path A through WM1 150 to the first mirror 130 or else to path B to the second mirror 135. Reflecting off either the first or second mirrors, the photon reaches the second beam splitter 120 and in this configuration approaches the third mirror 140 via path C rather than the fourth mirror 145 through WM2 155 via path D. Reflecting off the third mirror 140, the photon reaches the third beam splitter 125 to either the first or second deflectors 160, 165.

In this example, the basis state 10) means that the photon |0

is on the upper side of the beam splitter and state |1

means the photon 110 is on the lower side. Therefore, the general state of a photon ψ is represented by:

|ψ

=α|0

+β|1

,  (15)

where α and β are probability coefficients for the upper and lower sides.

Weak measurements can be performed of the operator |1

1| at two different points in time as shown the view 100. The operator |1

1| yields the probability that the photon occupies the lower side of the interferometer. Weak measurements of the operator therefore provide access to the weak values for the photon's occupation of paths A and D respectively, as well as access to the sequential weak value for the photon 110 to take the path AD through the apparatus.

The pre-selected state is defined by injecting the photon into the lower port of the first MZI, thus:

|ψ_(in)

=|1

,  (16)

corresponding to injecting the photon 110 into the lower input port of the interferometer. This produces a state where the photon 110 is localized completely in the upper state |0

along path C inside of the right MZI as MZI #2. This is because:

BMB|1

=−|0

,  (17)

where the beam-splitter operator B is denoted:

$\begin{matrix} {{B = {\frac{1}{\sqrt{2}}\left( {{{0\rangle}{\langle 1}} + {{1\rangle}{\langle 0}} + {i\; I}} \right)}},} & (18) \end{matrix}$

the mirror operator M is denoted:

M=iI,  (19)

with I the identity.

If the photon 110 is post-selected to arrive at Detector D₁ as 160, then the final state is:

|ψ_(fin)

=|0

.  (20)

The weak value of operator |1

1| inside of MZI #1 as 150, being denoted by (|1

1|₁)_(w), for photons that are members of the PPS ensemble defined by final state |ψ_(fin)

is:

$\begin{matrix} \begin{matrix} {\left( {{1\rangle}{1}_{1}} \right)_{w}^{D_{1}} = \frac{\langle{0{{{{BMBM}\left( {{1\rangle}{\langle 1}} \right)}B}}1}\rangle}{\langle{0{{BMBMB}}1}\rangle}} \\ {= \frac{\frac{- i}{\sqrt{2}}{\langle 1}\left( {{1\rangle}{\langle 1}} \right)\left( {{0\rangle} + {i{\langle 1}}} \right)}{\frac{- i}{\sqrt{2}}{\langle 1}\left( {{0\rangle} + {i{\langle 1}}} \right)}} \\ {= {+ 1.}} \end{matrix} & (21) \end{matrix}$

The weak value for the operator |1><1| inside of MZI #2, (|1><1|₂)_(w), for photons in the same PPS ensemble is:

$\begin{matrix} \begin{matrix} {\left( {{1\rangle}{\langle 1}_{2}} \right)_{w}^{D_{2}} = \frac{\langle{0{{{B\left( {{1\rangle}{\langle 1}} \right)}{MBMB}}}1}\rangle}{\langle{0{{BMBMB}}1}\rangle}} \\ {= \frac{{- i}{\langle{0{{B\left( {{1\rangle}{\langle 1}} \right)}}0}\rangle}}{{- i}{\langle{0{B}0}\rangle}}} \\ {= 0.} \end{matrix} & (22) \end{matrix}$

Hence, the weak value for the photon's occupation of path D is zero. One should note that:

(|1

1|₂)_(w)=0  (23)

for both PPS ensembles, and so the weak value of occupation of path C is equal to the expectation value,

(|1

1|₂)_(w)=(|1

1|₂)=0  (24)

This is expected given the complete destructive interference for this path. Due to the slight disturbance of the first weak measurement in MZI #1, the actual expectation value for MZI #2 can be established as:

(|1

1|₂)=g ₁ ²,  (25)

where g₁ is the coupling constant for WM1 as 150, so here again one obtains the approximation g₁ ²≅=0.

Finally, one can calculate the sequential weak value for the occupation of the combined path AD:

$\begin{matrix} \begin{matrix} {\left( {{{1\rangle}{\langle 1}_{2}},{{1\rangle}{\langle 1}_{1}}} \right)_{w}^{D_{1}} = \frac{{\langle 0}{{BM}\left( {{1\rangle}{\langle 1}} \right)}{{BM}\left( {{1\rangle}{\langle 1}} \right)}B{1\rangle}}{\langle{0{{BMBMB}}1}\rangle}} \\ {= \frac{\frac{1}{2}{\langle{0{B}1}\rangle}}{{- i}{\langle{0{B}0}\rangle}}} \\ {= \frac{\frac{1}{2\sqrt{2}}{\langle }\left( {{0\rangle} + {i{1\rangle}}} \right)}{\frac{- i}{\sqrt{2}}{\langle 0}\left( {{1\rangle} + {i{0\rangle}}} \right)}} \\ {= {+ {\frac{1}{2}.}}} \end{matrix} & (26) \end{matrix}$

For the PPS ensemble defined by photons arriving at Detector D₂ as 165 this weak value is:

$\begin{matrix} \begin{matrix} {\left( {{{1\rangle}{\langle 1}_{2}},{{1\rangle}{\langle 1}_{1}}} \right)_{w}^{D_{2}} = \frac{{\langle 1}{{BM}\left( {{1\rangle}{\langle 1}} \right)}{{BM}\left( {{1\rangle}{\langle 1}} \right)}B{1\rangle}}{\langle{1{{BMBMB}}1}\rangle}} \\ {= \frac{\frac{1}{2}{\langle{1{B}1}\rangle}}{{- i}{\langle{1{B}0}\rangle}}} \\ {= \frac{\frac{1}{2\sqrt{2}}{\langle 1}\left( {{0\rangle} + {i{1\rangle}}} \right)}{\frac{- i}{\sqrt{2}}{\langle 1}\left( {{1\rangle} + {i{0\rangle}}} \right)}} \\ {= {- {\frac{1}{2}.}}} \end{matrix} & (27) \end{matrix}$

From this one can observe that:

(|1

1|₂,|1

1|₁)_(w)≠(|1

1|₁)_(w)·(|1

1|₂)_(w),  (28)

such that the inequality signifies that the sequential weak value encodes correlations between the local weak measurement results of each photon 110.

FIG. 2 provides a plan diagram view 200 of a communication system between Bob 210 and Alice 215, with Eve 220 intercepting the trans-mission via classical eavesdropping techniques. Bob 210 uses a photon 230 to provide a communication signal. Bob's system includes three beam splitters 235, 240 and 245, four mirrors 250, 255, 260, and 265, two weak measurement devices 270, 275, and two detectors D₁ as 280 and D₂ as 285.

The photon 230 passes divides at the first splitter 235 either by path A through the first device 270 to reflect off the first mirror 250 or by path B to reflect off the second mirror 250. Both reflections direct the photon to the second splitter 240 that directs the photon 230 either by path C through the second device 275 to reflect off the third mirror 260 or else by path D towards Alice 215.

For path C, the photon 230 reflects off the third mirror 260 to reach the third splitter 245 and be directed to either the first or second detector 280, 285. Alice 215 has fifth and sixth mirrors 290, 295 and a third device 300. For path D, the photon 230 reaches the fifth mirror 290 to reflect off the sixth mirror 295 through the third device 300 and returns to Bob 210. Upon returning, the photon 230 reflects off the fourth mirror 265 to the third splitter 245 towards either detector 280, 285.

The purpose of this exemplary protocol is to enable Alice to send Bob a single classical bit of information such that the eavesdropper Eve is unable to obtain the bit. This process is described in the following eleven steps described below.

Step #1. Alice generates a list of random binary values of length K. This list will be referred to as the “raw key” henceforth. For each element of this list, the following steps (#2 through #11) are implemented.

Step #2. Bob sends N single photons (photon i at time t_(i)) into the interferometer as shown in the view 200. Each photon 210 is input into the same port so that each has:

|ψ_(in)

=|1

,  (29)

as with eqn. (16).

Step #3. Bob performs a weak measurement (with coupling strength g_(B)) of |1

1|₁ (occupation of path A) on each photon as it passes through MZI #1. Bob collects the individual pointer results into a list L₁ ordered by time.

Step #4. Alice performs a weak measurement (with coupling strength g_(A)) of |1

1|₂ (occupation of path D) on each photon as in passes through MZI #2. Alice collects the individual pointer results into a time ordered list L₂.

Step #5. Bob records the detector at which each photon arrives. Bob collects this into a time ordered list F. Using F, Bob collects the subset of L₁ associated with photons that arrived at detector D₁ and puts these elements in a time ordered list B₁. Similarly for the subset associated with detector D₂, Bob creates a list B₂.

Step #6. Bob calculates the arithmetic means (i.e., averages) μ₁ and μ₂ of lists B₁ and B₂. These should yield the values:

μ₁ =g _(B) Re└(|1

1|₁)_(w) ^(D) ¹ ┘=g _(B)·1,  (30)

and

μ₂ =g _(B) Re└(|1

1|₁)_(w) ^(D) ² ┘=g _(B)·0,  (31)

where g_(B) is the coupling constant for Bob's weak measurement. However, if Eve were to perform a projective measurement on each of the photons along path D then Bob would instead obtain the results:

$\begin{matrix} {\mu_{1} = {\mu_{2} = {g_{B} \cdot {\frac{1}{2}.}}}} & (32) \end{matrix}$

This is because Eve's measurement will break the correlation between Bob's weak measurement results and the photons' post-selection results. (The reason that Eve must perform an ideal measurement on the photons in order to eavesdrop is discussed below.)

Step #7. If Bob finds that the arithmetic means ∥₁ and μ₂ are too far from the expected values, he informs Alice that the channel is not secure and suggests that they begin the protocol over again. If Bob is satisfied that the weak values for (|1

1|₁)_(w) are 0 and 1 for the two PPS ensembles, then Bob can instruct Alice to proceed.

Step #8. Alice chooses the value of the bit she wants to send to Bob by reading the current element of the raw key list. If the raw key element is “1”, then she sends her list L₂ as is (i.e., without alteration) to Bob over an open classical channel. If the raw key element is “0”, then she cyclically shifts the members of the list L₂ by a non-zero number of elements. Note that the mean value of L₂ is invariant under this permutation.

Therefore, Eve has no way (even in principle) to infer the bit value that Alice chose from the classical message alone. This is the reason that Eve has to interfere with the photons. Eve needs to correlate Alice's weak measurement pointer results with some other information available to her as eavesdropper. The only way to accomplish this is to (directly) measure the photons collapsing the photon's which-path state. Exemplary embodiments thereby provide an advantage by using the photon's which-path information as the quantum observable. By contrast, techniques that employ other observables, e.g., the photon's polarization, involve passing every photon between Alice and Bob making them all accessible to Eve. In exemplary embodiments, Eve only has access to a small fraction of the total number of photons.

Step #9. Bob assumes that the list Alice sent is still ordered in the same manner as his lists L₁ and F (i.e., no shift in L₂). Using the post-selection information in F, Bob collects the subset of L₂ associated with photons that arrived at detector D₁ and deposits them in a time ordered list A₁. Similarly for the subset associated with detector D₂, Bob creates the list A₂.

Step #10. Bob multiplies the elements of the lists A₁ and B₁ to get product list R₁, and multiplies the elements of A₂ and B₂ to get product list R₂.

Step #11. Bob calculates the arithmetic mean values, v_(i) and V₂, of R₁ and R₂. For example, if

$\begin{matrix} {{v_{1} = {\frac{g_{A}g_{B}}{2} \cdot \left( \frac{1}{2} \right)}},{and}} & (33) \\ {{v_{2} = {\frac{g_{A}g_{B}}{2} \cdot \left( {- \frac{1}{2}} \right)}},} & (34) \end{matrix}$

then Bob infers that Alice sent a “1” as the raw key bit. Note that the ratio of the means v₁÷v₂ for this case is −1. By contrast, if

v ₁=0, and v ₂=0,  (35)

then Bob infers that Alice sent a “0” as the raw key bit.

When the entire raw key has been successfully transmitted, Alice and Bob implement error correction and privacy amplification on the raw key in order to distill a shared, secure private key of length K′. This private key possesses a shorter length than the raw key length K, such that K′<K.

Artisans of ordinary skill will recognize that the processes for cataloging detector results, averaging lists, determining values of coupling constants, etc. can be performed by a general purpose electronic processor using software, by custom hardware or any other automated system. These processors may be integrated into a unitary device or represent application-specific components devoted to at least one particular task.

Security of the information transmitted to Bob rests on the inability of Eve to infer that Alice has permuted the order of her local weak measurement results that have been transmitted to Bob. Eve lacks any manner even in principle to use only the transmitted list to know the weak measurement because there is no statistical difference between them. Therefore Eve must have more information about the photons than just the (non-post-selected) weak value of |1

1|₂.

Also, even in principle, Eve can't know the post-selection information (i.e., at which of the two detectors that each photon arrives) because this is determined and stored locally by Bob. Finally, Eve can't predict these values because each photon is equally likely to arrive at each detector.

Instead, the only action Eve can take is to perform her own pre- and/or post-selection on each photon as it passes. For instance, Eve can perform non-demolition ideal measurements of |1

1| on each photon before or after Alice's weak measurement.

In this manner, Alice's weak measurement results can now be placed into two different pre-selection ensembles, yielding different weak values when Eve does not observe a photon and when she does, then:

(|1

1|₂)_(w) ^(Eve0)=0  (36)

and

(|1

1|₂)_(w) ^(Eve1)=1,  (37)

respectively.

If these ensembles are large enough, Eve will be able to distinguish whether or not Alice has permuted her list of weak measurement pointer results. This is because if Alice permutes her results, the weak value that Eve calculates for the two pre-selected ensembles both must equal the expectation value:

|1

1|₂

=g _(B) ².  (38)

Therefore Eve's task is to accurate measure the average of Alice's pointer results conditioned by not detecting a photon, a₀, and the average conditioned on detecting a photon a₁.

Now suppose that it takes M photons for Bob to accurately determine the weak value of |1

1|₁ using his weak measurement results and post-selection information. Because the number of photons N, that Bob must send through the device in order to accurately determine Alice's bit choice is much larger than M, Eve could perform her own pre-selection measurements on each photon and would likely be able to determine the bit from the conditional averages of Alice's pointer results. However, Bob would very easily detect Eve's intervention because her pre-selection measurement along path D would have changed the weak value of his local weak measurement results of |1

1|₁.

For details on the effect of which-path measurements on the weak values of an observable equivalent to Bob's, see J. Tollaksen et al., “Quantum interference experiments . . . ”, New J. of Phys., 12 (2010) 013023. To detect Eve, Bob has the task (for the D₁ PPS ensemble) to distinguish between the two Gaussian probability distributions with means

${g_{B} \cdot \frac{1}{2}}\mspace{14mu} {and}\mspace{14mu} {g_{B} \cdot 1}$

(with unit variance) defined by Bob's MD wavefunction with and without Eve's strong measurement, respectively.

Recall that the case of pre-selection provides from eqn. (24) the expectation value:

(|1

1|₂)=0.  (39)

In the case of pre-selection as in eqn. (39) however, in order to infer Alice's bit value, Eve must distinguish between two Gaussian distributions with means:

α₀ =g _(A) ·g _(B) ²,  (40)

α₀ =g _(A)·0,  (41)

(with unit variance) derived from Alice's weak measurement pointer state with coupling strength g_(A).

As coupling strength g_(B) is decreased, Eve's probability of gaining information about the bit decreases at a rate faster than Bob's probability of detecting Eve's interaction with the photon. Therefore for large N (which is required for weak measurements), Bob can always detect Eve with very high probability and alert Alice before she transmits her pointer values, thereby preventing Eve from obtaining the bit value.

While certain features of the embodiments of the invention have been illustrated as described herein, many modifications, substitutions, changes and equivalents will now occur to those skilled in the art. It is, therefore, to be understood that the appended claims are intended to cover all such modifications and changes as fall within the true spirit of the embodiments. 

1. A method for distributing a shared secure key between first and second parties (Alice and Bob), said first party having a mirror, said second party having an interferometer pair that includes first, second and third beam splitters, and first and second detectors, said first party possessing a transfer list of random binary values that constitutes a raw key, said method comprising: sending a plurality of photons from the second party (Bob) into the interferometer pair at the first beam splitter; performing a first weak measurement that incorporates a first coupling strength g₄ on each photon as |1

1|₁ being a first pointer result; incorporating said first pointer result into a first time-ordered list L₁ for said each photon; performing a second weak measurement that incorporates a second coupling strength g_(B) by the first party (Alice) on said each photon that passes through the second beam splitter to the mirror as |1

1|₂ being a second pointer result; incorporating said second pointer result into a second time-ordered list L₂ for said each photon that passes through; recording identification as one of the first and second detectors at which said each photon arrives via the third beam splitter as respective first and second detector registrations; collecting said first and second detector registrations into a third time-ordered list F that correspond to said first time-ordered list L_(i) as respective first and second detection lists B₁ and B₂; determining first and second averages of said respective first and second detection lists; and comparing said first and second averages to verify existence of a non-trivial difference that indicates secure key distribution status.
 2. A method for distributing a shared secure key between first and second parties (Alice and Bob), said first party having a mirror, said second party having an interferometer pair that includes first, second and third beam splitters, and first and second detectors, said first party possessing a transfer list of random binary values that constitutes a raw key, said method comprising: sending a plurality of photons from the second party (Bob) into the interferometer pair at the first beam splitter; performing a first weak measurement on each photon as |1

1|₁ being a first pointer result; incorporating said first pointer result into a first time-ordered list L₁ for said each photon; performing a second weak by the first party (Alice) on said each photon that passes through the second beam splitter to the mirror as |1

1|₂ being a second pointer result; incorporating said second pointer result into a second time-ordered list L₂ for said each photon that passes through; recording identification as one of the first and second detectors at which said each photon arrives via the third beam splitter as respective first and second detector registrations; collecting said first and second detector registrations into a third time-ordered list F that correspond to said first time-ordered list L₁ as respective first and second detection lists B₁ and B₂; determining first and second averages of said respective first and second detection lists; comparing said first and second averages to verify existence of a non-trivial difference that indicates secure key distribution status; sending by the first party to the second party the transfer list from said second time-ordered list L₂ in one of an altered form to transmit a “0” and an unaltered form to transmit a “1”, said altered form shifting elements of each said second pointer result; collecting said first and second detector registrations from said third time-ordered list F corresponding to said transfer list as respective third and fourth detection lists A₁ and A₂; multiplying respective elements from said first and third detection lists to obtain a first product list R₁, and from said second and fourth detection lists to obtain a second product list R₂; and determining third and fourth averages of respective said first and second product lists, such that said “0” sent from the second party corresponds to both said third and fourth averages being zero, and said “1” sent from the second party corresponds to a ratio between said third and fourth averages being minus one.
 3. The method according to claim 1, further comprising: distilling the transfer list of length K from the raw key into private list of length K′ of a shared secure private key, such that K′<K, wherein said distilling includes error correction and privacy amplification of the raw key.
 4. (canceled)
 5. The method according to claim 2, wherein performing said first weak measurement incorporates a first coupling strength g_(A) and performing said second weak measurement incorporates a second coupling strength g_(B).
 6. The method according to claim 5, wherein said nontrivial difference corresponds to said first average equaling said second coupling strength g_(B), and said second average equaling zero.
 7. The method according to claim 5, wherein absence of said nontrivial difference corresponds to said first and second averages both equaling one-half of said second coupling strength as ½g_(B).
 8. The method according to claim 1, wherein the mirror represents a first mirror, the first party has a second mirror, and the interferometer pair of the second party further includes third, fourth, fifth and sixth mirrors for directing the photon to the beam splitters.
 9. The method according to claim 5, wherein said “1” sent corresponds to said third average equaling one-fourth said first coupling strength multiplied by said second coupling strength as ¼g_(A)g_(B), and said fourth average equaling minus one-fourth said first coupling strength multiplied by said second coupling strength as −¼g_(A)g_(B).
 10. A method for communication, between first and second parties (Alice and Bob), said first party having a mirror, said second party having an interferometer pair that includes first, second and third beam splitters, and first and second detectors, said method comprising: sending a plurality of photons from the second party (Bob) into the interferometer pair at the first beam splitter; performing a first weak measurement on each photon as |1

1|₁ being a first pointer result; incorporating said first pointer result into a first time-ordered list L_(i) for said each photon; performing a second weak measurement by the first party. (Alice) on said each photon that passes through the second beam splitter to the mirror as |1

1|₂ being a second pointer result; incorporating said second pointer result into a second time-ordered list L₂ for said each photon that passes through; recording identification as one of the first and second detectors at which said each photon arrives via the third beam splitter as respective first and second detector registrations; collecting said first and second detector registrations into a third time-ordered list F that correspond to said first time-ordered list L₁ as respective first and second detection lists B₁ and B₂; determining first and second averages of said respective first and second detection lists; comparing said first and second averages to verify existence of a non-trivial difference that indicates secure communication status; sending by the first party to the second party a transfer list from said second time-ordered list L₂ in one of an altered form to transmit a “0” and an unaltered form to transmit a “1”, said altered form shifting elements of each said second pointer result; collecting said first and second detector registrations from said third time-ordered list F corresponding to said transfer list as respective third and fourth detection lists A₁ and A₂; multiplying respective elements from said first and third detection lists to obtain a first product list R₁, and from said second and fourth detection lists to obtain a second product list R₂; and determining third and fourth averages of respective said first and second product lists, such that said “0” sent from the second party corresponds to both said third and fourth averages being zero, and said “1” sent from the second party corresponds to a ratio between said third and fourth averages being minus one.
 11. The method according to claim 10, wherein performing said first weak measurement incorporates a first coupling strength g_(A), and performing said second weak measurement incorporates a second coupling strength g_(B).
 12. The method according to claim 11, wherein said nontrivial difference corresponds to said first average equaling said second coupling strength g_(B), and said second average equaling zero.
 13. The method according to claim 12, wherein absence of said nontrivial difference corresponds to said first and second averages both equaling one-half of said second coupling strength ½g_(B).
 14. The method according to claim 11, wherein said “1” sent corresponds to said third average equaling one-fourth said first coupling strength multiplied by said second coupling strength as ¼g_(A)g_(B), and said fourth average equaling minus one-fourth said first coupling strength multiplied by said second coupling strength as −¼g_(A)g_(B).
 15. A receiver device for a first party (Bob) to communicate with a second party (Alice) having a mirror, said device comprising: an interferometer pair that includes: first, second and third beam splitters, and first and second detectors; a weak measurement device; a photon source that emits a plurality of photons to said first beam splitter; a weak measurement device for performing a first weak measurement on each photon as |1

1|₁ being a first pointer result; an accumulator for incorporating said first pointer result into a first time-ordered list L₁ for said each photon; a register for recording identification as one of said first and second detectors that said each photon arrives via the third beam splitter as respective first and second detector registrations; a discriminator for distinguishing said first and second detector registrations into a third time-ordered list F for said each photon; a collimator for collecting respective said first and second detector registrations from said third time-ordered list F that correspond to said first time-ordered list L_(i) as respective first and second detection lists B₁ and B₂; a processor for determining first and second averages of said respective first and second detection lists; and a comparator for comparing said first and second averages to verify existence of a non-trivial difference that indicates secure communication status.
 16. The device according to claim 15, wherein the second party (Alice) performs a second weak measurement on said each photon that passes through said second beam splitter to the mirror as |1

1|₂ being a second pointer result, incorporating said second pointer result into a second time-ordered list L₂ for said each photon that passes through, and the second party sends to the first party a transfer list from said second time-ordered list L₂ in one of an altered form to transmit a “0” and an unaltered form to transmit a “1”, said altered form shifting elements of each said second pointer result, said device further including: a collector for collecting respective said first and second detector registrations from said third time-ordered list F corresponding to said transfer list as respective third and fourth detection lists A₁ and A₂; a multiplier for multiplying respective elements from said first and third detection lists to obtain a first product list R₁, and from said second and fourth detection lists to obtain a second product list R₂; and a determiner for determining third and fourth averages of respective said first and second product lists, such that said “0” sent from the first party corresponds to both said third and fourth averages being zero, and said “1” sent from the first party corresponds to a ratio between said third and fourth averages being minus one.
 17. The method according to claim 1, wherein said nontrivial difference corresponds to said first average equaling said second coupling strength g_(B), and said second average equaling zero.
 18. The method according to claim 1, wherein absence of said nontrivial difference corresponds to said first and second averages both equaling one-half of said second coupling strength as ½g_(B).
 19. The method according to claim 1, wherein said “1” sent corresponds to said third average equaling one-fourth said first coupling strength multiplied by said second coupling strength as ¼g_(A)g_(B), and said fourth average equaling minus one-fourth said first coupling strength multiplied by said second coupling strength as −¼g_(A)g_(B).
 20. The method according to claim 2, further comprising: distilling the transfer list of length K from the raw key into private list of length K′ of a shared secure private key, such that K′<K, wherein said distilling includes error correction and privacy amplification of the raw key.
 21. The method according to claim 2, wherein the mirror represents a first mirror, the first party has a second mirror, and the interferometer pair of the second party further includes third, fourth, fifth and sixth mirrors for directing the photon to the beam splitters.
 22. The method according to claim 10, further comprising: distilling the transfer list of length K from the raw key into private list of length K′ of a shared secure private key, such that K′<K, wherein said distilling includes error correction and privacy amplification of the raw key.
 23. The method according to claim 10, wherein the mirror represents a first mirror, the first party has a second mirror, and the interferometer pair of the second party further includes third, fourth, fifth and sixth mirrors for directing the photon to the beam splitters. 